Generic SSL Certificate request

This document outlines the steps involved in getting a signed certificate from Thawte. These instruction are provided to cover off all the different brands of web servers. If you are using Microsoft Internet Information Server 4.0 or Apache-SSL on unix please follow the more detailed instructions for those web server.

Step 1. Generate a Private key and certificate request.

Thawte provides a good set of instructions for the different types of web servers at http://www.thawte.com/certs/server/keygen/. Please follow these instruction. Below are brief descriptions of what may be requested for during this process. Anything that is in bold must be filled in exactly as given right down to the capitals.

Note that the information you include in the certificate request must be exact and correct. Some data names are misleading. If you are not 100% sure of how to fill in a blank during this process please ask us as it will save a lot of time later. Also note that this process may create a Private Key with a password. If you lose the Private Key or forgets its password your certificate will be useless and you will have to start over and pay again. Note also that the Key must be kept safe as if it gets into public hands then all encryption efforts are lost and your system can be spoofed by others.
 
Field Name Description of what to enter
Password and Confirm Password This is the password for your private key. This should be something that can be remembered but nothing obvious like the server name. WRITE THIS DOWN NOW.
Bit Length This is the bit length of the key. Select the largest length possible which will likely be 512 or 1024.
Organization The University of Western Ontario
Organizational Unit Your Department or Faculty name. Please use its full name and not a short form or acronym.
Common Name This is the dns name of you web server. This should be what appears in the URL when you access the secure area of your server. (ie. www.dept.uwo.ca)
Country/Region CA
State/Province Ontario
City/Locality London
Your Name This should be the name of the technical contact for the web server. Most likely this will be you.
E-mail Address This should be the e-mail address of the technical contact for the web server. Note if you have a webmaster@dept.uwo.ca then this can be used instead of the person's personal e-mail account.
Phone Number This should be the phone number of the technical contact for the web server. Note if there is a help line for this server it can be used here. Whoever answers this line should know what to do with questions regarding the secure web server.

Step 2. Send the Certificate request to Thawte for signing.

During this process please read all information on these pages and if you have any questions stop the process and send them to web-certificates@julian.uwo.ca.

Step 3. Verification process and Payment.

Three e-mails will be sent by Thawte. One each to the Authorizing Contact, Technical Contact and to a member of ITS. The ITS representative will then contact the Authorizing Contact and Technical Contact to verify the request. Payment for the certificate of $100 US will be finalized. Once payment has been received ITS will approve the certificate signing and Thawte will issue the certificate.

Step 4. Retrieving the certificate.

When the certificate has been approved and signed Thawte will send another email to the Technical Contact. This email will contain a URL which will allow you to download your certificate. Goto this URL and enter in your password. This is the password you gave on the third page of Step 2. On the next screen you will be asked what format you want to download the certificate in. Select 'Standard Certificate Format' and use the 'Fetch Certificate' button to retrieve your certificate.
It will look a lot like the CSR. Copy it off this page into a text file. This file will be used to install the certificate into your web server. Backup this file along with the Private Key and keep them safe.

Step 5. Install your certificate.

At the end of the instructions from Thawte to generate a CSR used in step 1 are the required steps to install the certificate into your web server.

Getting Help

If you require assistance during any of this process please send an e-mail to web-certificates@julian.uwo.ca.